Grupo QuintoAndar | Non-Financial Risk Specialist
About Grupo QuintoAndar
We are Grupo QuintoAndar, the largest real estate ecosystem in Latin America. Guided by the purpose of helping people love where they live, we create technologies and solutions that simplify the entire housing journey, from renting to buying and selling.
Present in 6 countries (Brazil, Mexico, Argentina, Peru, Ecuador, and Panama) and with a technology hub in Portugal, we bring together more than 3,100 people in the challenge of transforming the sector. Supported by global investors such as SoftBank, General Atlantic, and Kaszek, we have already raised more than US$ 755 million and are a company valued at US$ 5.1 billion.
We lead the market transformation by being pioneers in the large-scale application of Artificial Intelligence in the real estate sector. Our platforms sum more than 50 million monthly accesses, managing more than 350 thousand active rental contracts and moving R$ 20 billion per year.
If you seek to solve complex problems with autonomy, cutting-edge technology, and impact on a massive scale, you can come in, the house is yours.
To learn more about our history, access: https://grupoquintoandar.com
Location and Work Model
Our Finance team operates in a hybrid model, combining the flexibility of remote work with in-person exchange at our office in São Paulo.
About the Area and the Challenge
We are looking for a person to technically lead the structuring and development of the company's non-financial risk agenda, contributing to the construction of the methodology, governance, processes, and tools necessary for integrated risk management.
This person will be responsible for progressively implementing the non-financial risk management model, starting with the most relevant exposures and the organization's priority areas.
The position will act as the second line of risk management, independently evaluating, guiding, and challenging the identification, assessment, response, and monitoring of risks conducted by business areas and specialist functions.
The professional must possess solid experience in operational risks, Enterprise Risk Management — ERM —, governance, or risk methodologies. It is not necessary to have the same level of depth in all non-financial risk categories, but comprehensive knowledge, the ability to mobilize specialists, and a willingness to develop new competencies are expected.
The role will initially be exercised as an individual position of high seniority and technical leadership, with the responsibility of building the foundations that could support the future evolution of the non-financial risk structure.
Main responsibilities
Structure and implement the methodology and governance model for the company's non-financial risks.
Develop and maintain the corporate risk taxonomy, promoting consistency between different areas and existing methodologies.
Define the implementation roadmap for the non-financial risk agenda, prioritizing relevant exposures, critical areas, and pilot initiatives.
Structure and conduct risk identification and assessment processes, including Risk and Control Self-Assessment — RCSA.
Develop criteria, scales, and guidelines for assessing probability, impact, controls, inherent risk, and residual risk.
Support the definition and review of appetite, tolerance, and limits related to non-financial risks.
Develop key risk indicators — KRIs —, alert triggers, and escalation criteria.
Structure the process for capturing, classifying, and analyzing incidents, operational losses, and near misses.
Develop risk maps, scenario analyses, impact assessments, and executive reports.
Support the selection, implementation, and evolution of the GRC tool used for risk registration, monitoring, and reporting.
Support areas in defining risk responses, including mitigation, acceptance, transfer, or discontinuation of exposure.
Monitor action plans related to priority risks and perform escalation of delays or relevant exposures.
Participate in risk assessments of new products, processes, systems, partners, projects, and strategic initiatives.
Evaluate the existence and adequacy of controls reported by the areas, challenging assumptions and conclusions when necessary.
Coordinate interaction with specialist areas responsible for specific risks, such as Information Security, Privacy, Compliance, Legal, Fraud, Business Continuity, and Third-Party Management.
Act in conjunction with Internal Controls, avoiding overlap of responsibilities and leveraging existing assessments, controls, and evidence.
Support the definition and update of policies, standards, procedures, and guidelines related to risk management.
Promote training and awareness actions to strengthen the first line's accountability for managing its risks.
Prepare materials for the Risk Committee, Audit Committee, senior leadership, and other governance forums.
Contribute to the definition of the operational model and future capacity needs of the non-financial risk area.
Scope of risks
The position must have a comprehensive view of non-financial risks and the ability to coordinate assessments related to:
processes and operations;
technology and systems;
information security and cyber risks;
third parties and suppliers;
business continuity and operational resilience;
internal and external fraud;
people and operational capacity;
organizational changes;
new products, projects, and initiatives;
models, data, and automations;
reputation;
strategy execution;
operational compliance.
The professional is not expected to be a technical specialist in all these categories. For topics that have specialist areas, the role will focus on methodological integration, consolidation of exposures, independent challenging, and corporate reporting.
Education and experience
Higher education in Administration, Economics, Accounting, Engineering, Law, Technology, or related fields.
Relevant experience in one or more of the following areas:
Corporate Risk Management;
Operational Risks;
Enterprise Risk Management — ERM;
Internal Controls;
Internal Audit;
Compliance;
Risk consulting.
Experience in the construction, implementation, or review of risk management methodologies.
Experience in conducting risk assessments, RCSA, building risk maps, and monitoring action plans.
Knowledge of frameworks such as COSO ERM and ISO 31000.
Experience in building governance models, indicators, and executive reports.
Ability to analyze end-to-end processes and identify causes, impacts, controls, and interdependencies.
Experience in conducting projects or agendas involving different areas and stakeholders.
Advanced knowledge of Excel or Google Sheets.
Experience with risk management tools, GRC, or data visualization.
Intermediate or advanced English for reading technical materials and interacting in corporate environments.
Desirable knowledge
Experience with operational risks in technology companies, financial services, marketplaces, or payment methods.
Experience in the implementation or administration of GRC tools.
Knowledge of methodologies for managing incidents, operational losses, and near misses.
Familiarity with third-party risks, business continuity, technology, information security, or fraud.
Knowledge of SOX, COSO Internal Control, and the Three Lines model.
Experience in defining appetite and tolerance for non-financial risks.
Knowledge of scenario analysis methods and operational resilience assessment.
Differentials
Certifications such as CRMA, CIA, CISA, ISO 31000, CBCP, or similar.
Experience in implementing Enterprise Risk Management — ERM — programs.
Experience in organizations subject to regulated environments.
Experience presenting topics to the Risk Committee, Audit Committee, Board of Directors, or senior leadership.
Expected behavioral profile
High level of autonomy and ability to structure an agenda still under development.
Ability to act as technical leadership and methodological reference.
Critical thinking, systemic vision, and prioritization ability.
Ability to build processes progressively, starting with pilots and priority exposures.
Ability to connect seemingly isolated risks and identify corporate impacts.
Objective communication and skill to adapt messages to technical and executive audiences.
Ability to influence and negotiate without depending on hierarchical authority.
Firm posture to challenge assessments, plans, deadlines, and exposure levels.
Ability to mobilize specialist areas and coordinate multidisciplinary discussions.
Pragmatism to propose solutions compatible with the maturity stage and business reality.
Organization, sense of priority, and ability to work with multiple fronts.
Genuine interest in building processes, methodologies, tools, and routines from the ground up.
Collaborative posture, without losing independence, objectivity, and critical sense.
How is our selection process?
We design a transparent, direct journey focused on evaluating your technical and behavioral potential and offering you the opportunity to meet our teams and career paths, structured as follows:
Application and Screening;
People Interview;
Hiring Manager Interview;
Case;
Stakeholder Interview;
Offer!
Important: We evaluate all applications individually and guarantee feedback to everyone. All communication is done via email, so make sure to whitelist the domain @quintoandar.com.br in your inbox.
Benefits
We offer a complete package focused on your health, well-being, family, and development:
Remuneration: Competitive salary, Profit Sharing (PLR - for eligible roles), and Variable Remuneration (for eligible roles).
Health and Well-being: Health Plan, Dental, Life Insurance, Wellhub (Gympass), and QuintoCare (free psychological, legal, social, and financial support).
Quality of Life: Meal and Food Vouchers, Birthday Day Off, Mother's Day, and Father's Day.
Flexibility: Home Office Allowance and Work From Anywhere (WFA) program.
Family and Care: Daycare Allowance, Atypical Parenting Allowance, Extended Parental Leave, and Kit Leiturinha.
Education and career: Partnerships with educational institutions;
Diversity & Inclusion at Grupo QuintoAndar
We value diversity and want everyone to feel welcome here — regardless of your age, gender identity, sexual orientation, race, color, ethnicity, origin, disability, religion, or any other characteristic. All our vacancies are open to everyone! You will notice some questions about diversity in the application form. In affirmative vacancies, the information may be used to verify your alignment with the target audience of the opportunity, which, in those cases, may have a disqualifying character. For non-affirmative vacancies, this data will be used anonymously, exclusively to monitor and improve our inclusion practices in selection processes and without impact on your application.
Privacy and Data Protection
Grupo QuintoAndar operates in compliance with privacy and data protection laws, including, but not limited to, the General Personal Data Protection Law - LGPD (Law No. 13.709/2018), and ensures the security of your personal data. To learn more, access our Privacy Notice for Candidates. If you have questions or wish to exercise your rights as a data subject, contact us through the Service Channel.